Skip to content

SecurityNot yet confirmed elsewhere1 publisher3 min readPublished

88 breaches, 2.15 billion records, and 41 leaks that nobody can reset

A compiled timeline of identity-verification failures since 2011 puts nearly half the incidents in the category where what leaked was the face or the document itself.

The Watch · Security desk

How we use AISend a correction

What happened

  • Mysterium VPN has published a timeline of 88 documented incidents since 2011 in which data collected to verify identity or age was breached, exposed or sold.
  • The confirmed and researcher-verified total across those incidents is 2.15 billion records.
  • Claims made by attackers and data sellers would add another 4.54 billion records that nobody has verified.

Why it matters

  • constraint For nearly half the catalogued incidents there is no remediation step to fund: you cannot reissue a fingerprint, so the response ends at notification and monitoring.
  • exposure Because AU10TIX sits in front of TikTok, Uber and X, an exposure at the vendor reaches those platforms' users, who never chose the vendor and cannot audit it.
  • decision Firms adding age gates have to decide whether outsourcing transfers the liability or only the storage, and the timeline argues it does the latter.
  • contradiction The headline volume depends on which figure you accept: verified counts and criminal boasts differ by billions, and only one of them belongs in a risk model.

The rate is the part the report leaves on the table. Thirty-seven of the 88 incidents fall inside the 32 months from January 2024 to August 2026 [7]. Treat the timeline as starting in January 2011 and the other 51 spread across roughly 156 months, which is about one incident a quarter in the older period against better than one a month in the recent one, a rate around three and a half times higher [18]. Some of that gap is an artefact of counting: a 2013 exposure is harder to find than a 2025 one. The rest is supply. Mandates create databases, and databases are what leave.

The concentration is the more useful detail for anyone buying this as a service. AU10TIX, which verifies identity for TikTok, Uber and X, left admin credentials exposed for more than a year [10]. Sumsub disclosed a support-system intrusion that ran undetected for 18 months [11]. Persona, which handles age verification for Discord and Roblox, exposed its own frontend configuration [12]. The report's claim is that every major vendor of this era appears somewhere in the timeline, naming AU10TIX, IDMerit, Sumsub, Persona and inVOID [1]. Outsourcing an age gate does not take the ID off your risk register. It moves the document into a company whose client list is the reason to attack it, and whose incidents you will hear about second.

Discord's case shows where the harm lands. The roughly 70,000 government IDs exposed through a third-party support provider belonged to users who had challenged an age-verification decision, meaning people who were trying to correct the system's judgement about them, and Discord carried on expanding age checks afterwards [9]. Tea, built as a women-only safety platform, lost verification selfies out of an open storage bucket, and the images later showed up on 4chan [8].

Government registries are in the same list at larger scale. Argentina's national identity system leaked 45 million records including ID scans and selfies [13], and France's ANTS, the agency that issues French identity documents, confirmed 11.7 million people affected in a 2026 breach [14]. Those two alone account for about 56.7 million [20], with India's Aadhaar, Thailand's visitor database, the Philippines' voter rolls and Brazil's tax registry also on the timeline [15].

Two cautions on the headline number. The compiler is a VPN company, Mysterium, which is worth holding in mind while reading its framing even though the incidents are individually checkable [3]. And the 4.54 billion attributed to attacker and seller claims is more than twice the verified figure [19], so the number to argue about is 2.15 billion [4]. The number to budget against is 41: the incidents where ID scans, verification selfies, fingerprints and biometric templates were part of what leaked, none of which can be reissued [6]. SecurityAffairs' reading is that leaning on a reputable third-party provider is not sufficient protection for firms weighing build against outsource [16], and the report's own conclusion is that this is one failure mode repeated across fifteen years and every type of organisation that decided to collect this category of data [2].

What to watch

  • Whether regulators writing age-check mandates add retention limits or outright no-store rules for source documents and selfies.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence46
Adoption62
Hype gap+22
Incentives71
Confidence48
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The report states that every major identity-verification vendor of the current era, naming AU10TIX, IDMerit, Sumsub, Persona and inVOID, has appeared in its timeline.

    ReportedSupportedSource: Mysterium VPN report, quoted by SecurityAffairs2 sources— create a free account to open themView cited source
  2. [2]

    The report concludes that the timeline shows one failure mode repeated across 88 incidents, fifteen years, and every type of organisation that has decided to collect this category of data.

    ReportedSupportedSource: Mysterium VPN report, quoted by SecurityAffairs2 sources— create a free account to open themView cited source
  3. [3]

    A report from Mysterium VPN compiles 88 documented incidents since 2011 in which data collected specifically to verify someone's identity or age was breached, exposed, or sold.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. securityaffairs.com

    1 article · August 26, 2026

    88 ID Verification Breaches Show the Cost of Collecting Identity Data

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories